[PATCH 4/4] drm/xe: Implement VM snapshot support for BO's and userptr
Souza, Jose
jose.souza at intel.com
Mon Jan 15 21:02:39 UTC 2024
On Fri, 2024-01-12 at 13:41 +0100, Maarten Lankhorst wrote:
> Since we cannot immediately capture the BO's and userptr, perform it in
> 2 stages. The immediate stage takes a reference to each BO and userptr,
> while a delayed worker captures the contents and then frees the
> reference.
>
> This is required because in signaling context, no locks can be taken, no
> memory can be allocated, and no waits on userspace can be performed.
>
> With the delayed worker, all of this can be performed very easily,
> without having to resort to hacks.
[ 3978.658699] xe 0000:00:02.0: [drm] Timedout job: seqno=4294967169, guc_id=3, flags=0x8
[ 3978.659006] ------------[ cut here ]------------
[ 3978.659031] DEBUG_LOCKS_WARN_ON(lock->magic != lock)
[ 3978.659037] WARNING: CPU: 0 PID: 16087 at kernel/locking/mutex.c:582 __mutex_lock+0x50d/0xb80
[ 3978.659079] Modules linked in: snd_hda_codec_hdmi snd_ctl_led snd_hda_codec_realtek snd_hda_codec_generic ledtrig_audio xe drm_ttm_helper
drm_suballoc_helper gpu_sched drm_gpuvm drm_exec i2c_algo_bit drm_buddy drm_display_helper ttm x86_pkg_temp_thermal mei_pxp mei_hdcp wmi_bmof coretemp
crct10dif_pclmul snd_hda_intel snd_intel_dspcfg crc32_pclmul snd_hda_codec video ghash_clmulni_intel kvm_intel snd_hwdep e1000e snd_hda_core i2c_i801
ptp snd_pcm pps_core i2c_smbus mei_me mei wmi fuse
[ 3978.659206] CPU: 0 PID: 16087 Comm: kworker/u16:0 Not tainted 6.7.0-rc5-zeh-xe+ #1183
[ 3978.659229] Hardware name: Dell Inc. Latitude 5420/01M3M4, BIOS 1.27.0 03/17/2023
[ 3978.659251] Workqueue: gt-ordered-wq drm_sched_job_timedout [gpu_sched]
[ 3978.659277] RIP: 0010:__mutex_lock+0x50d/0xb80
[ 3978.659292] Code: ff 85 c0 0f 84 7d fb ff ff 8b 15 a2 bd bb 00 85 d2 0f 85 6f fb ff ff 48 c7 c6 d1 a5 3a 82 48 c7 c7 6a 35 3a 82 e8 e3 25 41 ff
<0f> 0b e9 55 fb ff ff 31 c9 31 d2 4c 89 e7 e8 00 82 48 ff 84 c0 0f
[ 3978.659333] RSP: 0018:ffffc90002f67c40 EFLAGS: 00010286
[ 3978.659349] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
[ 3978.659367] RDX: 0000000000000002 RSI: 0000000000000027 RDI: 00000000ffffffff
[ 3978.659386] RBP: ffffc90002f67cd0 R08: 00000000fffeffff R09: 0000000000000001
[ 3978.659405] R10: 00000000fffeffff R11: ffff888287080000 R12: ffff88811090eca8
[ 3978.659423] R13: 0000000000000000 R14: ffff88811090e838 R15: 0000000000000001
[ 3978.659441] FS: 0000000000000000(0000) GS:ffff888287800000(0000) knlGS:0000000000000000
[ 3978.659461] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 3978.659475] CR2: 00007f8fbdd49ac0 CR3: 0000000005649006 CR4: 0000000000770ef0
[ 3978.659492] PKRU: 55555554
[ 3978.659501] Call Trace:
[ 3978.659510] <TASK>
[ 3978.659520] ? __mutex_lock+0x50d/0xb80
[ 3978.659532] ? __warn+0x7c/0x170
[ 3978.659545] ? __mutex_lock+0x50d/0xb80
[ 3978.659557] ? report_bug+0x189/0x1c0
[ 3978.659569] ? handle_bug+0x36/0x70
[ 3978.659578] ? exc_invalid_op+0x13/0x60
[ 3978.659588] ? asm_exc_invalid_op+0x16/0x20
[ 3978.659601] ? __mutex_lock+0x50d/0xb80
[ 3978.659613] ? find_held_lock+0x2b/0x80
[ 3978.659625] ? xe_vm_snapshot_capture+0x2c/0x1f0 [xe]
[ 3978.659707] ? xe_vm_snapshot_capture+0x2c/0x1f0 [xe]
[ 3978.659761] xe_vm_snapshot_capture+0x2c/0x1f0 [xe]
[ 3978.659817] xe_devcoredump+0x181/0x2b0 [xe]
[ 3978.659860] guc_exec_queue_timedout_job+0x1ab/0x730 [xe]
[ 3978.659916] ? find_held_lock+0x2b/0x80
[ 3978.659930] drm_sched_job_timedout+0x77/0xe0 [gpu_sched]
[ 3978.659951] ? process_one_work+0x18d/0x4d0
[ 3978.659965] process_one_work+0x1f4/0x4d0
[ 3978.659978] worker_thread+0x1d8/0x3c0
[ 3978.659990] ? rescuer_thread+0x390/0x390
[ 3978.660004] kthread+0xfb/0x130
[ 3978.660020] ? kthread_complete_and_exit+0x20/0x20
[ 3978.660037] ret_from_fork+0x28/0x40
[ 3978.660049] ? kthread_complete_and_exit+0x20/0x20
[ 3978.660068] ret_from_fork_asm+0x11/0x20
[ 3978.660082] </TASK>
[ 3978.660089] irq event stamp: 2542781
[ 3978.660101] hardirqs last enabled at (2542781): [<ffffffff81d1fdba>] _raw_spin_unlock_irqrestore+0x4a/0x70
[ 3978.660132] hardirqs last disabled at (2542780): [<ffffffff81d1fb8a>] _raw_spin_lock_irqsave+0x4a/0x50
[ 3978.660163] softirqs last enabled at (2542754): [<ffffffff811346e2>] irq_exit_rcu+0x82/0xe0
[ 3978.660196] softirqs last disabled at (2542747): [<ffffffff811346e2>] irq_exit_rcu+0x82/0xe0
[ 3978.660229] ---[ end trace 0000000000000000 ]---
[ 3978.660290] xe 0000:00:02.0: [drm] Xe device coredump has been created
>
> Signed-off-by: Maarten Lankhorst <maarten.lankhorst at linux.intel.com>
> ---
> drivers/gpu/drm/xe/xe_devcoredump.c | 34 ++++-
> drivers/gpu/drm/xe/xe_devcoredump_types.h | 8 ++
> drivers/gpu/drm/xe/xe_vm.c | 149 ++++++++++++++++++++++
> drivers/gpu/drm/xe/xe_vm.h | 5 +
> 4 files changed, 194 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/gpu/drm/xe/xe_devcoredump.c b/drivers/gpu/drm/xe/xe_devcoredump.c
> index 68abc0b195be..1ffae670f739 100644
> --- a/drivers/gpu/drm/xe/xe_devcoredump.c
> +++ b/drivers/gpu/drm/xe/xe_devcoredump.c
> @@ -16,6 +16,7 @@
> #include "xe_guc_ct.h"
> #include "xe_guc_submit.h"
> #include "xe_hw_engine.h"
> +#include "xe_vm.h"
>
> /**
> * DOC: Xe device coredump
> @@ -58,11 +59,21 @@ static struct xe_guc *exec_queue_to_guc(struct xe_exec_queue *q)
> return &q->gt->uc.guc;
> }
>
> +static void xe_devcoredump_deferred_snap_work(struct work_struct *work)
> +{
> + struct xe_devcoredump_snapshot *ss = container_of(work, typeof(*ss), work);
> +
> + xe_force_wake_get(gt_to_fw(ss->gt), XE_FORCEWAKE_ALL);
> + if (ss->vm)
> + xe_vm_snapshot_capture_delayed(ss->vm);
> + xe_force_wake_put(gt_to_fw(ss->gt), XE_FORCEWAKE_ALL);
> +}
> +
> static ssize_t xe_devcoredump_read(char *buffer, loff_t offset,
> size_t count, void *data, size_t datalen)
> {
> struct xe_devcoredump *coredump = data;
> - struct xe_devcoredump_snapshot *ss;
> + struct xe_devcoredump_snapshot *ss = &coredump->snapshot;
> struct drm_printer p;
> struct drm_print_iterator iter;
> struct timespec64 ts;
> @@ -72,12 +83,14 @@ static ssize_t xe_devcoredump_read(char *buffer, loff_t offset,
> if (!data || !coredump_to_xe(coredump))
> return -ENODEV;
>
> + /* Ensure delayed work is captured before continuing */
> + flush_work(&ss->work);
> +
> iter.data = buffer;
> iter.offset = 0;
> iter.start = offset;
> iter.remain = count;
>
> - ss = &coredump->snapshot;
> p = drm_coredump_printer(&iter);
>
> drm_printf(&p, "**** Xe Device Coredump ****\n");
> @@ -98,6 +111,10 @@ static ssize_t xe_devcoredump_read(char *buffer, loff_t offset,
> if (coredump->snapshot.hwe[i])
> xe_hw_engine_snapshot_print(coredump->snapshot.hwe[i],
> &p);
> + if (coredump->snapshot.vm) {
> + drm_printf(&p, "\n**** VM state ****\n");
> + xe_vm_snapshot_print(coredump->snapshot.vm, &p);
> + }
>
> return count - iter.remain;
> }
> @@ -111,11 +128,15 @@ static void xe_devcoredump_free(void *data)
> if (!data || !coredump_to_xe(coredump))
> return;
>
> + cancel_work_sync(&coredump->snapshot.work);
> +
> xe_guc_ct_snapshot_free(coredump->snapshot.ct);
> xe_guc_exec_queue_snapshot_free(coredump->snapshot.ge);
> for (i = 0; i < XE_NUM_HW_ENGINES; i++)
> if (coredump->snapshot.hwe[i])
> xe_hw_engine_snapshot_free(coredump->snapshot.hwe[i]);
> + xe_vm_snapshot_free(coredump->snapshot.vm);
> + memset(&coredump->snapshot, 0, sizeof(coredump->snapshot));
>
> coredump->captured = false;
> drm_info(&coredump_to_xe(coredump)->drm,
> @@ -137,6 +158,9 @@ static void devcoredump_snapshot(struct xe_devcoredump *coredump,
> ss->snapshot_time = ktime_get_real();
> ss->boot_time = ktime_get_boottime();
>
> + ss->gt = q->gt;
> + INIT_WORK(&ss->work, xe_devcoredump_deferred_snap_work);
> +
> cookie = dma_fence_begin_signalling();
> for (i = 0; q->width > 1 && i < XE_HW_ENGINE_MAX_INSTANCE;) {
> if (adj_logical_mask & BIT(i)) {
> @@ -151,6 +175,8 @@ static void devcoredump_snapshot(struct xe_devcoredump *coredump,
>
> coredump->snapshot.ct = xe_guc_ct_snapshot_capture(&guc->ct, true);
> coredump->snapshot.ge = xe_guc_exec_queue_snapshot_capture(q);
> + if (q->vm)
> + coredump->snapshot.vm = xe_vm_snapshot_capture(q->vm);
>
> for_each_hw_engine(hwe, q->gt, id) {
> if (hwe->class != q->hwe->class ||
> @@ -161,6 +187,9 @@ static void devcoredump_snapshot(struct xe_devcoredump *coredump,
> coredump->snapshot.hwe[id] = xe_hw_engine_snapshot_capture(hwe);
> }
>
> + if (ss->vm)
> + queue_work(system_unbound_wq, &ss->work);
> +
> xe_force_wake_put(gt_to_fw(q->gt), XE_FORCEWAKE_ALL);
> dma_fence_end_signalling(cookie);
> }
> @@ -194,3 +223,4 @@ void xe_devcoredump(struct xe_exec_queue *q)
> xe_devcoredump_read, xe_devcoredump_free);
> }
> #endif
> +
> diff --git a/drivers/gpu/drm/xe/xe_devcoredump_types.h b/drivers/gpu/drm/xe/xe_devcoredump_types.h
> index 7fdad9c3d3dd..17ae3e3597b0 100644
> --- a/drivers/gpu/drm/xe/xe_devcoredump_types.h
> +++ b/drivers/gpu/drm/xe/xe_devcoredump_types.h
> @@ -12,6 +12,7 @@
> #include "xe_hw_engine_types.h"
>
> struct xe_device;
> +struct xe_gt;
>
> /**
> * struct xe_devcoredump_snapshot - Crash snapshot
> @@ -26,6 +27,11 @@ struct xe_devcoredump_snapshot {
> /** @boot_time: Relative boot time so the uptime can be calculated. */
> ktime_t boot_time;
>
> + /** @gt: Affected GT, used by forcewake for delayed capture */
> + struct xe_gt *gt;
> + /** @work: Workqueue for deffered capture outside of signaling context */
> + struct work_struct work;
> +
> /* GuC snapshots */
> /** @ct: GuC CT snapshot */
> struct xe_guc_ct_snapshot *ct;
> @@ -33,6 +39,8 @@ struct xe_devcoredump_snapshot {
> struct xe_guc_submit_exec_queue_snapshot *ge;
> /** @hwe: HW Engine snapshot array */
> struct xe_hw_engine_snapshot *hwe[XE_NUM_HW_ENGINES];
> + /** @vm: Snapshot of VM state */
> + struct xe_vm_snapshot *vm;
> };
>
> /**
> diff --git a/drivers/gpu/drm/xe/xe_vm.c b/drivers/gpu/drm/xe/xe_vm.c
> index e1c07c6ecbaf..c16d0fd89411 100644
> --- a/drivers/gpu/drm/xe/xe_vm.c
> +++ b/drivers/gpu/drm/xe/xe_vm.c
> @@ -3229,3 +3229,152 @@ int xe_analyze_vm(struct drm_printer *p, struct xe_vm *vm, int gt_id)
>
> return 0;
> }
> +
> +struct xe_vm_snapshot {
> + unsigned long num_snaps;
> + struct {
> + uint64_t ofs, bo_ofs;
> + unsigned long len;
> + struct xe_bo *bo;
> + void *data;
> + struct mm_struct *mm;
> + } snap[];
> +};
> +
> +struct xe_vm_snapshot *xe_vm_snapshot_capture(struct xe_vm *vm)
> +{
> + unsigned long num_snaps = 0, i;
> + struct xe_vm_snapshot *snap = NULL;
> + struct drm_gpuva *gpuva;
> +
> + mutex_lock(&vm->snap_mutex);
> + drm_gpuvm_for_each_va(gpuva, &vm->gpuvm) {
> + if (gpuva->flags & XE_VMA_DUMPABLE)
> + num_snaps++;
> + }
> +
> + if (num_snaps)
> + snap = kvzalloc(offsetof(struct xe_vm_snapshot, snap[num_snaps]), GFP_NOWAIT);
> + if (!snap)
> + goto out_unlock;
> +
> + snap->num_snaps = num_snaps;
> + i = 0;
> + drm_gpuvm_for_each_va(gpuva, &vm->gpuvm) {
> + struct xe_vma *vma = gpuva_to_vma(gpuva);
> + struct xe_bo *bo = vma->gpuva.gem.obj ?
> + gem_to_xe_bo(vma->gpuva.gem.obj) : NULL;
> +
> + if (!(gpuva->flags & XE_VMA_DUMPABLE))
> + continue;
> +
> + snap->snap[i].ofs = xe_vma_start(vma);
> + snap->snap[i].len = xe_vma_size(vma);
> + if (bo) {
> + snap->snap[i].bo = xe_bo_get(bo);
> + snap->snap[i].bo_ofs = xe_vma_bo_offset(vma);
> + } else if (xe_vma_is_userptr(vma)) {
> + if (mmget_not_zero(vma->userptr.notifier.mm))
> + snap->snap[i].mm = vma->userptr.notifier.mm;
> + else
> + snap->snap[i].data = ERR_PTR(-EFAULT);
> + snap->snap[i].bo_ofs = xe_vma_userptr(vma);
> + } else {
> + snap->snap[i].data = ERR_PTR(-ENOENT);
> + }
> + i++;
> + }
> +
> +out_unlock:
> + mutex_unlock(&vm->snap_mutex);
> + return snap;
> +}
> +
> +void xe_vm_snapshot_capture_delayed(struct xe_vm_snapshot *snap)
> +{
> + for (int i = 0; i < snap->num_snaps; i++) {
> + struct xe_bo *bo = snap->snap[i].bo;
> + struct iosys_map src;
> + int err;
> +
> + if (IS_ERR(snap->snap[i].data))
> + continue;
> +
> + snap->snap[i].data = kvmalloc(snap->snap[i].len, GFP_USER);
> + if (!snap->snap[i].data) {
> + snap->snap[i].data = ERR_PTR(-ENOMEM);
> + goto cleanup_bo;
> + }
> +
> + if (bo) {
> + dma_resv_lock(bo->ttm.base.resv, NULL);
> + err = ttm_bo_vmap(&bo->ttm, &src);
> + if (!err) {
> + xe_map_memcpy_from(xe_bo_device(bo),
> + snap->snap[i].data,
> + &src, snap->snap[i].bo_ofs,
> + snap->snap[i].len);
> + ttm_bo_vunmap(&bo->ttm, &src);
> + }
> + dma_resv_unlock(bo->ttm.base.resv);
> + } else {
> + void __user *userptr = (void __user *)(size_t)snap->snap[i].bo_ofs;
> + kthread_use_mm(snap->snap[i].mm);
> +
> + if (!copy_from_user(snap->snap[i].data, userptr, snap->snap[i].len))
> + err = 0;
> + else
> + err = -EFAULT;
> + kthread_unuse_mm(snap->snap[i].mm);
> + mmput(snap->snap[i].mm);
> + snap->snap[i].mm = NULL;
> + }
> +
> + if (err) {
> + kvfree(snap->snap[i].data);
> + snap->snap[i].data = ERR_PTR(err);
> + }
> +
> +cleanup_bo:
> + xe_bo_put(bo);
> + snap->snap[i].bo = NULL;
> + }
> +}
> +
> +void xe_vm_snapshot_print(struct xe_vm_snapshot *snap, struct drm_printer *p)
> +{
> + unsigned long i, j;
> +
> + for (i = 0; i < snap->num_snaps; i++) {
> + if (IS_ERR(snap->snap[i].data))
> + goto uncaptured;
> +
> + for (j = 0; j < snap->snap[i].len; j += 64) {
> + uint32_t *x = snap->snap[i].data + j;
> +
> + drm_printf(p, "[%llx] = { %x, %x, %x, %x, %x, %x, %x, %x, %x, %x, %x, %x, %x, %x, %x, %x }\n",
> + snap->snap[i].ofs + j, x[0], x[1], x[2], x[3], x[4], x[5], x[6], x[7],
> + x[8], x[9], x[10], x[11], x[12], x[13], x[14], x[15]);
> + }
> + continue;
> +
> +uncaptured:
> + drm_printf(p, "Unable to capture range [%llx-%llx]: %li\n",
> + snap->snap[i].ofs, snap->snap[i].ofs + snap->snap[i].len - 1,
> + PTR_ERR(snap->snap[i].data));
> + }
> +}
> +
> +void xe_vm_snapshot_free(struct xe_vm_snapshot *snap)
> +{
> + unsigned long i;
> +
> + for (i = 0; i < snap->num_snaps; i++) {
> + if (!IS_ERR(snap->snap[i].data))
> + kvfree(snap->snap[i].data);
> + xe_bo_put(snap->snap[i].bo);
> + if (snap->snap[i].mm)
> + mmput(snap->snap[i].mm);
> + }
> + kvfree(snap);
> +}
> diff --git a/drivers/gpu/drm/xe/xe_vm.h b/drivers/gpu/drm/xe/xe_vm.h
> index cf2f96e8c1ab..9a7513d31b2b 100644
> --- a/drivers/gpu/drm/xe/xe_vm.h
> +++ b/drivers/gpu/drm/xe/xe_vm.h
> @@ -261,3 +261,8 @@ static inline void vm_dbg(const struct drm_device *dev,
> { /* noop */ }
> #endif
> #endif
> +
> +struct xe_vm_snapshot *xe_vm_snapshot_capture(struct xe_vm *vm);
> +void xe_vm_snapshot_capture_delayed(struct xe_vm_snapshot *snap);
> +void xe_vm_snapshot_print(struct xe_vm_snapshot *snap, struct drm_printer *p);
> +void xe_vm_snapshot_free(struct xe_vm_snapshot *snap);
More information about the Intel-xe
mailing list